TS-240228-10-AgentTesla-53ad73.exe Trojan AgentTesla Analysis

Trojan AgentTesla
Updated on 2024-03-06 (2 months ago)
Checked by Online Virus Scanner
Online Virus Checkerv.1.0.168.174
DB Version:2024-03-06 01:00:29

Trojan.Win32.AgentTesla.tr

AgentTesla is a Remote Access Trojan (RAT) built on the .Net framework, primarily utilized to acquire initial access to systems. It's frequently employed within the framework of Malware-As-A-Service (MaaS). Within this illicit business model, individuals referred to as "initial access brokers" (IAB) offer their specialized expertise to criminal groups seeking to exploit corporate networks. As an initial-stage malware, AgentTesla facilitates remote access to a compromised system, subsequently permitting the downloading of more advanced secondary tools, including ransomware.

FileTS-240228-10-AgentTesla-53ad73.exe
Checked2024-03-06 02:04:18
MD574f10daaa5e14d58229e06611fae17cf
SHA153ad732f953aea07bc3e83a50aff1d8575b17b21
SHA2560be4823639fe4ec61328f6424383080c516cd83680a9f9f74f093c435f3161c6
SHA51271965b8a8e15d693274436113816f0343a9edbe54354537adf93caae87d79c42f39246a14b4149b1eb2d79e3cbf1de39fd17696e866151c873709404dd3f6d6e
Imphashf34d5f2d4577ed6d9ceec516c1f5a744
File Size1130496 bytes

Trojan.Win32.AgentTesla.tr Removal

Trojan.Win32.AgentTesla.tr Removal

Gridinsoft has the capability to identify and eliminate Trojan.Win32.AgentTesla.tr without requiring further user intervention.

  • Start by downloading Gridinsoft Anti-Malware to your computer.
  • Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  • Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  • Click on the "Standard Scan" button.
  • After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  • If prompted, restart your system to complete the removal process.

File Version Information

Translation0x0000 0x04b0
CommentsSteam
CompanyNameSteam
FileDescriptionSteam
FileVersion1.0.0.0
InternalNameVex Cleaner.exe
LegalCopyrightCopyright © 2023
LegalTrademarksSteam
OriginalFilenameVex Cleaner.exe
ProductNameSteam
ProductVersion1.0.0.0
Assembly Version1.0.0.0

Portable Executable Info

Image Base:0x00400000
Entry Point:0x0051467e
Compilation:2091-03-16 01:40:25
Checksum:0x00000000 (Actual: 0x0011b26c)
OS Version:4.0
PDB Path:D:\Malaia.cc cleaner_2\Malaia.cc cleaner\Cleaner src\Cleaner\obj\Debug\Vex Cleaner.pdb
PEiD:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
Sign:The PE file does not contain a certificate table.
Sections:3
Imports: mscoree,
Exports: 0
Resources:2

Sections

Name Virtual Address Virtual Size Raw Size MD5 Entropy
.text 0x00002000 0x00112684 0x00112800 e2aeb454c164c774c200efc50f5eb777 7.98
.rsrc 0x00116000 0x00001228 0x00001400 4c29de6b309ae2900a7939af1f30b368 4.90
.reloc 0x00118000 0x0000000c 0x00000200 7452a54b245890912ada8d27e8d32186 0.10

Leave a comment*

Share your thoughts or insights about this file. Do you align with our conclusion?

*Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Please Wait...

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware